Teraz kolega bardzo skrupulanie poprosze cala prawda o dysku.
Czy to jest skutek pracy HDD regeneratora?
I powiem jedna prawda jezeli mamy urwany lancuch extended to 3 partycja wogole nie mogla byc widoczna przez system!!
boot ntfs drugiej partycji
offset(w bajtach)/rozmiar(w bajtach) :
D/1 - Liczba sektorow w klastrze - 08= 8 lba
28/4 - Mladsze slowo ilosci sektorow partycji - 9D F4 27 06
2C/4 - Starsze slowo ilosci sektorow partycji - 00 00 00 00
30/4 - Mladsze slowo numeru pierwszego klastra MFT - 04 00 0 00
34/4 - Starsze slowo numeru pierwszego klastra MFT - 00 00 00 00
38/4 - Mladsze slowo numeru pierwszego klastra MFTmirror - 00 00 08 00
3C/4 - Starsze slowo numeru pierwszego klastra MFTmirror - 00 00 00 00
627F49D - 103281821 LBA
mft 04 - 4 klaster na tym obszaru to jest ostani sektor z signatura BAAD9
mftmirror - 80000h - 524288 klaster
wie kolega jezeli by taki system plikow ktos zaprojektowal, mozna byloby powiedziec ze jest nie bardzo madrym ( mozna powiedziec i mocniej ) .
mft i mftmirror ulokowac w pierwszych klastrach prawie razem ( jak w pierwszym rozdziale tak i w tym ), jaki sens wogole wtedy mirrora? I na dodatek tego nie mogl zrobic system !!
To jest obszar gdzie powinien byl byc boot extended ( a mamy tylko boot'y ntfs nu i slady zabujcy danych hdd regeneratora )
przy tym mamy wyrazny boot copy offset 0x0800 pierwszej partycji z czego wynika ze nastepny musial byc boot extended ( a mamy tu boot ntfs)
=>
0x0800 EB 52 90 4E 54 46 53 20 20 20 20 00 02 08 00 00 ëR�NTFS .....
0x0810 00 00 00 00 00 F8 00 00 3F 00 FF 00 3F 00 00 00 .....ø..?.ÿ.?...
0x0820 00 00 00 00 80 00 80 00 35 F8 8B 06 00 00 00 00 ....€.€.5ø‹.....
0x0830 00 00 0C 00 00 00 00 00 55 02 00 00 00 00 00 00 ........U.......
0x0840 F6 00 00 00 01 00 00 00 A0 74 26 B4 90 26 B4 54 ö....... t&´�&´T
0x0850 00 00 00 00 FA 33 C0 8E D0 BC 00 7C FB B8 C0 07 ....ú3ÀŽÐ¼.|û¸À.
0x0860 8E D8 E8 16 00 B8 00 0D 8E C0 33 DB C6 06 0E 00 ŽØè..¸..ŽÀ3ÛÆ...
0x0870 10 E8 53 00 68 00 0D 68 6A 02 CB 8A 16 24 00 B4 .èS.h..hj.ËŠ.$.´
0x0880 08 CD 13 73 05 B9 FF FF 8A F1 66 0F B6 C6 40 66 .Í.s.¹ÿÿŠñf.¶Æ@f
0x0890 0F B6 D1 80 E2 3F F7 E2 86 CD C0 ED 06 41 66 0F .¶Ñ€â?÷â†ÍÀí.Af.
0x08A0 B7 C9 66 F7 E1 66 A3 20 00 C3 B4 41 BB AA 55 8A ·Éf÷áf£ .ôA»ªUŠ
0x08B0 16 24 00 CD 13 72 0F 81 FB 55 AA 75 09 F6 C1 01 .$.Í.r.�ûUªu.öÁ.
0x08C0 74 04 FE 06 14 00 C3 66 60 1E 06 66 A1 10 00 66 t.þ...Ãf`..f¡..f
0x08D0 03 06 1C 00 66 3B 06 20 00 0F 82 3A 00 1E 66 6A ....f;. ..‚:..fj
0x08E0 00 66 50 06 53 66 68 10 00 01 00 80 3E 14 00 00 .fP.Sfh....€>...
0x08F0 0F 85 0C 00 E8 B3 FF 80 3E 14 00 00 0F 84 61 00 .…..è³ÿ€>....„a.
0x0900 B4 42 8A 16 24 00 16 1F 8B F4 CD 13 66 58 5B 07 ´BŠ.$...‹ôÍ.fX[.
0x0910 66 58 66 58 1F EB 2D 66 33 D2 66 0F B7 0E 18 00 fXfX.ë-f3Òf.·...
0x0920 66 F7 F1 FE C2 8A CA 66 8B D0 66 C1 EA 10 F7 36 f÷ñþŠÊf‹ÐfÁê.÷6
0x0930 1A 00 86 D6 8A 16 24 00 8A E8 C0 E4 06 0A CC B8 ..†ÖŠ.$.ŠèÀä..̸
0x0940 01 02 CD 13 0F 82 19 00 8C C0 05 20 00 8E C0 66 ..Í..‚..ŒÀ. .ŽÀf
0x0950 FF 06 10 00 FF 0E 0E 00 0F 85 6F FF 07 1F 66 61 ÿ...ÿ....…oÿ..fa
0x0960 C3 A0 F8 01 E8 09 00 A0 FB 01 E8 03 00 FB EB FE Ã ø.è.. û.è..ûëþ
0x0970 B4 01 8B F0 AC 3C 00 74 09 B4 0E BB 07 00 CD 10 ´.‹ð¬<.t.´.»..Í.
0x0980 EB F2 C3 0D 0A 41 20 64 69 73 6B 20 72 65 61 64 ëòÃ..A disk read
0x0990 20 65 72 72 6F 72 20 6F 63 63 75 72 72 65 64 00 error occurred.
0x09A0 0D 0A 4E 54 4C 44 52 20 69 73 20 6D 69 73 73 69 ..NTLDR is missi
0x09B0 6E 67 00 0D 0A 4E 54 4C 44 52 20 69 73 20 63 6F ng...NTLDR is co
0x09C0 6D 70 72 65 73 73 65 64 00 0D 0A 50 72 65 73 73 mpressed...Press
0x09D0 20 43 74 72 6C 2B 41 6C 74 2B 44 65 6C 20 74 6F Ctrl+Alt+Del to
0x09E0 20 72 65 73 74 61 72 74 0D 0A 00 00 00 00 00 00 restart........
0x09F0 00 00 00 00 00 00 00 00 83 A0 B3 C9 00 00 55 AA ........ƒ ³É..Uª
0x0A00 EB 52 90 4E 54 46 53 20 20 20 20 00 02 08 00 00 ëR�NTFS .....
0x0A10 00 00 00 00 00 F8 00 00 3F 00 FF 00 3F 00 00 00 .....ø..?.ÿ.?...
0x0A20 00 00 00 00 80 00 80 00 90 DC 45 0C 00 00 00 00 ....€.€.�ÜE.....
0x0A30 04 00 00 00 00 00 00 00 00 00 08 00 00 00 00 00 ................
0x0A40 F6 00 00 00 01 00 00 00 21 7E 3C F2 E4 14 37 AF ö.......!~<òä.7¯
0x0A50 00 00 00 00 FA 33 C0 8E D0 BC 00 7C FB B8 C0 07 ....ú3ÀŽÐ¼.|û¸À.
0x0A60 8E D8 E8 16 00 B8 00 0D 8E C0 33 DB C6 06 0E 00 ŽØè..¸..ŽÀ3ÛÆ...
0x0A70 10 E8 53 00 68 00 0D 68 6A 02 CB 8A 16 24 00 B4 .èS.h..hj.ËŠ.$.´
0x0A80 08 CD 13 73 05 B9 FF FF 8A F1 66 0F B6 C6 40 66 .Í.s.¹ÿÿŠñf.¶Æ@f
0x0A90 0F B6 D1 80 E2 3F F7 E2 86 CD C0 ED 06 41 66 0F .¶Ñ€â?÷â†ÍÀí.Af.
0x0AA0 B7 C9 66 F7 E1 66 A3 20 00 C3 B4 41 BB AA 55 8A ·Éf÷áf£ .ôA»ªUŠ
0x0AB0 16 24 00 CD 13 72 0F 81 FB 55 AA 75 09 F6 C1 01 .$.Í.r.�ûUªu.öÁ.
0x0AC0 74 04 FE 06 14 00 C3 66 60 1E 06 66 A1 10 00 66 t.þ...Ãf`..f¡..f
0x0AD0 03 06 1C 00 66 3B 06 20 00 0F 82 3A 00 1E 66 6A ....f;. ..‚:..fj
0x0AE0 00 66 50 06 53 66 68 10 00 01 00 80 3E 14 00 00 .fP.Sfh....€>...
0x0AF0 0F 85 0C 00 E8 B3 FF 80 3E 14 00 00 0F 84 61 00 .…..è³ÿ€>....„a.
0x0B00 B4 42 8A 16 24 00 16 1F 8B F4 CD 13 66 58 5B 07 ´BŠ.$...‹ôÍ.fX[.
0x0B10 66 58 66 58 1F EB 2D 66 33 D2 66 0F B7 0E 18 00 fXfX.ë-f3Òf.·...
0x0B20 66 F7 F1 FE C2 8A CA 66 8B D0 66 C1 EA 10 F7 36 f÷ñþŠÊf‹ÐfÁê.÷6
0x0B30 1A 00 86 D6 8A 16 24 00 8A E8 C0 E4 06 0A CC B8 ..†ÖŠ.$.ŠèÀä..̸
0x0B40 01 02 CD 13 0F 82 19 00 8C C0 05 20 00 8E C0 66 ..Í..‚..ŒÀ. .ŽÀf
0x0B50 FF 06 10 00 FF 0E 0E 00 0F 85 6F FF 07 1F 66 61 ÿ...ÿ....…oÿ..fa
0x0B60 C3 A0 F8 01 E8 09 00 A0 FB 01 E8 03 00 FB EB FE Ã ø.è.. û.è..ûëþ
0x0B70 B4 01 8B F0 AC 3C 00 74 09 B4 0E BB 07 00 CD 10 ´.‹ð¬<.t.´.»..Í.
0x0B80 EB F2 C3 0D 0A 41 20 64 69 73 6B 20 72 65 61 64 ëòÃ..A disk read
0x0B90 20 65 72 72 6F 72 20 6F 63 63 75 72 72 65 64 00 error occurred.
0x0BA0 0D 0A 4E 54 4C 44 52 20 69 73 20 6D 69 73 73 69 ..NTLDR is missi
0x0BB0 6E 67 00 0D 0A 4E 54 4C 44 52 20 69 73 20 00 FE ng...NTLDR is .þ
0x0BC0 FF FF 07 FE FF FF 3F 00 00 00 9E F4 27 06 00 FE ÿÿ.þÿÿ?...žô'..þ
0x0BD0 FF FF 05 FE FF FF DD F4 27 06 9E 0C 49 0C 00 00 ÿÿ.þÿÿÝô'.ž.I...
0x0BE0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
0x0BF0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 55 AA ..............Uª
0x8800 EB 52 90 4E 54 46 53 20 20 20 20 00 02 08 00 00 ëR�NTFS .....
0x8810 00 00 00 00 00 F8 00 00 3F 00 FF 00 3F 00 00 00 .....ø..?.ÿ.?...
0x8820 00 00 00 00 80 00 80 00 9D F4 27 06 00 00 00 00 ....€.€.�ô'.....
0x8830 04 00 00 00 00 00 00 00 00 00 08 00 00 00 00 00 ................
0x8840 F6 00 00 00 01 00 00 00 69 0F DC A9 C1 E5 77 13 ö.......i.Ü©Áåw.
0x8850 00 00 00 00 FA 33 C0 8E D0 BC 00 7C FB B8 C0 07 ....ú3ÀŽÐ¼.|û¸À.
0x8860 8E D8 E8 16 00 B8 00 0D 8E C0 33 DB C6 06 0E 00 ŽØè..¸..ŽÀ3ÛÆ...
0x8870 10 E8 53 00 68 00 0D 68 6A 02 CB 8A 16 24 00 B4 .èS.h..hj.ËŠ.$.´
0x8880 08 CD 13 73 05 B9 FF FF 8A F1 66 0F B6 C6 40 66 .Í.s.¹ÿÿŠñf.¶Æ@f
0x8890 0F B6 D1 80 E2 3F F7 E2 86 CD C0 ED 06 41 66 0F .¶Ñ€â?÷â†ÍÀí.Af.
0x88A0 B7 C9 66 F7 E1 66 A3 20 00 C3 B4 41 BB AA 55 8A ·Éf÷áf£ .ôA»ªUŠ
0x88B0 16 24 00 CD 13 72 0F 81 FB 55 AA 75 09 F6 C1 01 .$.Í.r.�ûUªu.öÁ.
0x88C0 74 04 FE 06 14 00 C3 66 60 1E 06 66 A1 10 00 66 t.þ...Ãf`..f¡..f
0x88D0 03 06 1C 00 66 3B 06 20 00 0F 82 3A 00 1E 66 6A ....f;. ..‚:..fj
0x88E0 00 66 50 06 53 66 68 10 00 01 00 80 3E 14 00 00 .fP.Sfh....€>...
0x88F0 0F 85 0C 00 E8 B3 FF 80 3E 14 00 00 0F 84 61 00 .…..è³ÿ€>....„a.
0x8900 B4 42 8A 16 24 00 16 1F 8B F4 CD 13 66 58 5B 07 ´BŠ.$...‹ôÍ.fX[.
0x8910 66 58 66 58 1F EB 2D 66 33 D2 66 0F B7 0E 18 00 fXfX.ë-f3Òf.·...
0x8920 66 F7 F1 FE C2 8A CA 66 8B D0 66 C1 EA 10 F7 36 f÷ñþŠÊf‹ÐfÁê.÷6
0x8930 1A 00 86 D6 8A 16 24 00 8A E8 C0 E4 06 0A CC B8 ..†ÖŠ.$.ŠèÀä..̸
0x8940 01 02 CD 13 0F 82 19 00 8C C0 05 20 00 8E C0 66 ..Í..‚..ŒÀ. .ŽÀf
0x8950 FF 06 10 00 FF 0E 0E 00 0F 85 6F FF 07 1F 66 61 ÿ...ÿ....…oÿ..fa
0x8960 C3 A0 F8 01 E8 09 00 A0 FB 01 E8 03 00 FB EB FE Ã ø.è.. û.è..ûëþ
0x8970 B4 01 8B F0 AC 3C 00 74 09 B4 0E BB 07 00 CD 10 ´.‹ð¬<.t.´.»..Í.
0x8980 EB F2 C3 0D 0A 41 20 64 69 73 6B 20 72 65 61 64 ëòÃ..A disk read
0x8990 20 65 72 72 6F 72 20 6F 63 63 75 72 72 65 64 00 error occurred.
0x89A0 0D 0A 4E 54 4C 44 52 20 69 73 20 6D 69 73 73 69 ..NTLDR is missi
0x89B0 6E 67 00 0D 0A 4E 54 4C 44 52 20 69 73 20 63 6F ng...NTLDR is co
0x89C0 6D 70 72 65 73 73 65 64 00 0D 0A 50 72 65 73 73 mpressed...Press
0x89D0 20 43 74 72 6C 2B 41 6C 74 2B 44 65 6C 20 74 6F Ctrl+Alt+Del to
0x89E0 20 72 65 73 74 61 72 74 0D 0A 00 00 00 00 00 00 restart........
0x89F0 00 00 00 00 00 00 00 00 83 A0 B3 C9 00 00 55 AA ........ƒ ³É..Uª
0xC800 42 41 41 44 39 00 03 00 3E EC 4F 26 09 00 00 00 BAAD9...>ìO&....
0xC810 01 00 01 00 38 00 05 00 A0 01 08 00 00 04 08 00 ....8... .......
0xC820 00 00 00 00 00 00 00 00 04 00 00 00 00 00 00 00 ................
0xC830 B3 00 08 00 00 00 00 00 10 00 00 00 60 00 00 00 ³...........`...
0xC840 00 00 18 00 00 00 00 00 48 00 00 00 18 00 00 00 ........H.......
0xC850 40 1B C7 9C 02 C6 CF 01 60 1B C7 9C 02 C6 CF 01 @.Çœ.ÆÏ.`.Çœ.ÆÏ.
0xC860 60 1B C7 9C 02 C6 CF 01 60 1B C7 9C 02 C6 CF 01 `.Çœ.ÆÏ.`.Çœ.ÆÏ.
0xC870 0E 00 08 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
0xC880 00 00 00 00 00 01 00 00 00 00 00 00 00 00 00 00 ................
0xC890 00 00 00 00 00 00 00 00 30 00 00 00 68 00 08 00 ........0...h...
0xC8A0 00 00 18 00 00 00 01 00 4A 00 08 00 18 00 01 00 ........J.......
0xC8B0 05 00 00 00 00 00 05 00 40 1B C7 9C 0A C6 CF 01 ........@.Çœ.ÆÏ.
0xC8C0 60 1B C7 9C 02 C6 CF 01 60 1B C7 9C 02 C6 CF 01 `.Çœ.ÆÏ.`.Çœ.ÆÏ.
0xC8D0 60 1B C7 9C 02 C6 CF 01 08 80 00 00 00 00 00 00 `.Çœ.ÆÏ..€......
0xC8E0 00 80 00 00 00 00 00 00 06 00 00 00 00 00 00 00 .€..............
0xC8F0 04 03 24 00 4D 00 46 00 54 00 00 00 00 00 00 00 ..$.M.F.T.......
0xC900 80 00 00 00 48 00 00 00 01 00 40 00 00 00 02 00 €...H.....@.....
0xC910 00 00 00 00 00 00 00 00 EF 52 09 00 00 00 00 00 ........ïR......
0xC920 40 00 00 00 00 00 00 00 00 00 2F 05 09 00 00 00 @........./.....
0xC930 00 00 2F 05 09 00 00 00 00 00 2F 05 09 00 00 00 ../......./.....
0xC940 12 F0 5B 04 08 00 01 00 B0 00 00 00 50 00 00 00 .ð[.....°...P...
0xC950 01 00 40 00 00 00 03 00 00 00 00 00 00 00 00 00 ..@.............
0xC960 02 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 ........@.......
0xC970 00 30 08 00 00 00 00 00 78 29 08 00 00 00 00 00 .0......x)......
0xC980 78 29 09 00 00 00 00 00 11 01 02 31 01 76 78 2F x).........1.vx/
0xC990 39 01 D9 BE 1B 00 BB B5 FF FF FF FF 09 00 00 00 9.Ù¾..»µÿÿÿÿ....
0xC9A0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
0xC9B0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
0xC9C0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
0xC9D0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
0xC9E0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
0xC9F0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 B3 00 ..............³.
Jak widzimy nie ma i sladu Extended , Ale mamy dobry przklad dzialania HDD RECENERATORA to jest to o czym ja stale uprzedzam ludzie ,wyzerowane obszary i sektory zapisany bezwzglendnie z uszkodzona summa kontrolna, signatura pliku po offsecie 0xC800 ( a to nasz mft pierwszy sektor) musiala byc FILE* a jest BAAD9 przy tym teraz zawartosc uszkodzona a summa kontrolna dobra =>
Teraz poprosze na nastepne obszary
109836500 - 109836507
114030770 lba -114030800 lba
213118280 lba - 213118380 lba